Skip to content
nerlo.ai

Terms of Service

Draft: not reviewed by counsel.

This is a working draft written to describe what the Nerlo registry actually does today, in the same voice as our Privacy and data processing pages. It has not been reviewed by a lawyer and is not legal advice. Anywhere you see a box marked TODO(JesseTop), a fact this document would normally state (our legal entity, governing law, how disputes get resolved, a liability cap, a contact address) has not been decided yet — we show the gap rather than guess at it.

These terms cover your use of nerlo.ai and the Nerlo registry: the public listing of MCP servers, Claude Skills, Gemini Extensions, and Cursor Rules, and the automated per-scanner scorecards we publish for each. By using the site or its API you agree to them.

The service

The registry is a transparency layer, not a marketplace: we don't host, distribute, or modify the packages we scan. Each listing links back to the package's own source (its repository or registry entry), and every scorecard shows the scanners we ran, the findings each reported, and the tool version, never a single averaged number standing in for the rest.

No findings does not mean no risk. Nerlo aggregates automated scanner output; automated scanning is one layer of defence, not a substitute for review.

Scan results are automated and reflect the version we scanned at the time we scanned it. Nothing on this site is a certification, an endorsement, or a guarantee that a package is safe to run. See Methodology for how scores are computed and what each scanner can and cannot see.

Accounts

Browsing the registry needs no account. Where an account is required (submitting a package, saving a project), sign-in is OAuth (Google, GitHub) or an email magic link. We never see or store a password. You're responsible for activity under your account and for keeping your sign-in method secure.

You can delete your account at any time from Account Settings. Deletion starts a 14-day grace period during which you can cancel it; after that window it's final. Some records (audit history, and appeal history from the period when appeals were accepted, referencing a package you authored) are retained afterward with your identifying details removed, as described on the data processing page.

Plans and billing

Nerlo is free to use. Browsing, the public API, and the CLI cost nothing, and we do not currently sell paid plans — there is no checkout and nothing to purchase. If we begin offering paid tiers we will update these terms before doing so, and any charge would require you to agree to them first. If payments become available they will be handled by Stripe under Stripe's own terms; we would never see or store your card details, only a Stripe-issued customer reference.

Submitting a package

Authors can submit a package for scanning. By doing so you represent that you have the right to submit it: as its maintainer, or because it's already published under a license that permits this. Registry data about published software (names, repository links, scan results) is public information; we publish it as part of the transparency layer described above.

We may decline to list, or may remove, a submission, including for findings that place it outside what the registry covers. That decision is recorded rather than made silently.

A removal is not permanent, but it is not reversed by contesting it either. We do not operate an appeal or dispute process and do not edit scan results on request. What restores a removed package is a later scan that no longer finds what caused the removal — the same rule, applied to new evidence, with no judgement call in between. Because a removed package's source is blocked from being scanned again, ask us to unblock it once you've shipped the fix; that gets you a fresh scan, and the scan decides, not us.

Acceptable use

Changes to the service or these terms

The registry is under active development and its feature set can change. We may update this page as the product changes; the version here is the current one. We don't currently have a notification mechanism for terms changes beyond the page itself: TODO(JesseTop): process for notifying users of material changes to these terms.

Disclaimer and limitation of liability

The service, including every scan result, is provided on an “as is” basis without warranties of any kind, to the fullest extent applicable law permits. We don't guarantee the registry is uninterrupted, error-free, or that any package's scorecard is complete. See the disclaimer above.

A specific liability cap, and any carve-outs required by the jurisdiction this section will ultimately be governed by, are not set: TODO(JesseTop): liability cap and any statutory carve-outs.

Governing law and disputes

TODO(JesseTop): governing law, jurisdiction, and how disputes get resolved (courts vs. arbitration)

Who you're agreeing with

TODO(JesseTop): the legal entity operating Nerlo, and a contact address

This page describes current, verifiable practice wherever it makes a factual claim, and marks what isn't decided as a TODO rather than filling it in. It is maintained alongside Privacy and the data processing register and should be updated in the same PR as any change to how accounts, billing, or scanning actually work, and replaced with counsel-reviewed text before this draft banner comes down.